The Deal Isn't Done When They Say Yes: Security, Legal, and Procurement

By Louie Bernstein•

On a bigger deal, the verbal yes doesn't close anything. It starts a second sale. Security wants a review. Legal wants to redline your contract. Procurement wants forms, terms, and a lower price. Treat each one as a real stage in your pipeline, with an owner on your side and a named person on theirs, and start all three at once. If you don't, the deal sits in limbo and you end up chasing it yourself.

Key Takeaways:

  • The verbal yes is a starting line, not a finish line. Bigger deals have three more steps: security, legal, and procurement.
  • Security is a real blocker. 38% of organizations lost revenue or bids because they lacked a compliance certification (Secureframe, 2026).
  • Put each step in your CRM as a stage with exit criteria and an owner. If it isn't in the CRM, it never happened.
  • Find out how they buy in the first meetings, not after the yes. Ask five questions early.
  • Run security, legal, and procurement in parallel. Waiting for one to finish before starting the next is how deals stall.
  • The rep stays the deal owner. The founder answers specific questions, then steps back.

You know this feeling. The champion says, "We're in. Let's do this." You tell the team. You put it in the forecast for this month.

Then a 200-line security questionnaire shows up. Two weeks later, their legal team sends back your contract covered in red. Then procurement asks you to fill out a vendor form and "sharpen your pencil" on price. The month ends. The deal is still open.

And here's the part that hurts. Your rep has never seen any of this before. So who answers the security questions? You. Who reads the redlines? You. Who calls the champion to find out why procurement went quiet? You. You spent a year getting out of sales, and one big deal just put you back in.

None of this is bad luck. It's the normal way bigger companies buy. The problem is that most small sales teams don't plan for it. They treat security, legal, and procurement as surprises at the end, when they should be steps on the map from day one.

On a bigger deal, the yes is when the second sale starts. Plan for it like a sale, because it is one.
Run the paperwork in parallel, not in a line. Top track, how founders run it (sequential): verbal yes, then security questionnaire, then legal redlines, then procurement setup, then signature, each step waiting for the one before it while the founder chases every handoff. Bottom track, how it should run (parallel): the week the champion confirms intent, three threads start together, each with an owner: security review (send your packet), legal (send your contract early), and procurement (ask for vendor forms). All three end at signature, signed sooner than the line above. 38% of organizations lost revenue or bids for lack of a compliance certification (Secureframe 2026 Benchmark Report, 255 professionals surveyed).

Why do deals stall after the verbal yes?

Late-stage deals rarely die in one big moment. They drift. Here are the three reasons I see most.

Nobody on your side owns the paperwork

Your rep owns the relationship with the champion. But who owns the security questionnaire? Who tracks the redlines? Who sends the tax form to accounts payable? If the answer is "whoever gets to it," the answer is really "the founder, at 10 p.m."

It starts too late

Most teams wait for the verbal yes before they even ask about security or legal. Then they run each step one at a time. Security finishes, then legal starts. Legal finishes, then procurement starts. Each handoff adds dead time, and nobody on the buyer's side is in a hurry to fill it.

It isn't in your pipeline

Look at your CRM stages. Most small teams have something like Discovery, Demo, Proposal, Negotiation, Closed. Everything after the yes gets lumped into "Negotiation." So a deal can sit there for two months and look exactly like a deal that will sign tomorrow. You can't manage what you can't see.

This isn't a small problem. Secureframe's 2026 benchmark report surveyed 255 security, compliance, and IT professionals. 38% said they had lost revenue or competitive bids because they lacked a compliance certification. 47% said it had delayed their sales cycles (Secureframe, 2026). That's just the security step. Legal and procurement add their own waits on top.

Make security, legal, and procurement real pipeline stages

The fix starts in your CRM. Add each step as its own stage, or as a required checklist inside one late stage. Either works. What matters is that each step has an owner, a date, and a clear finish line.

Here's how I'd write them. Notice that each one ends with something the buyer does, not something you hope for:

  • Security review: their security reviewer confirms in writing that you passed, or lists what's left.
  • Legal: both sides agree on the contract language. No open redlines.
  • Procurement: you're set up as a vendor, payment terms are agreed, and the signer is named with a date.

Stages should move on buyer action, not on hope. I explain how to write those finish lines in why your pipeline stages need exit criteria. Once these stages exist, you can finally see where a big deal is stuck. And if it isn't in the CRM, it never happened.

Related ReadingYour Pipeline Stages Need Exit Criteria →

Find the buying process in the first meetings

The best time to learn how a company buys is before they've decided to buy. Early on, your champion is curious and helpful. After the yes, they're busy and a little embarrassed that it's taking so long.

So ask early. Don't wait for a "paperwork" call. Work these questions into your first two or three meetings, and write the answers in the deal record. If your champion can't answer them, that tells you something too. Either they haven't bought something like this before, or they aren't as close to the decision as you thought. I cover that second problem in the multi-threading playbook.

Five questions to ask before the verbal yes

Copy this into your discovery notes

  1. "Who signs a contract this size, and have they signed one like it before?"
  2. "Does your security team need to review new vendors? What do they usually ask for?"
  3. "Will legal want to use our contract or yours? Who on your legal team handles it?"
  4. "What does procurement need to set up a new vendor, and how long did that take last time?"
  5. "If you wanted to start on a certain date, what would have to happen by when?"

That last question is the important one. It gets the champion to build the timeline with you, working back from their date. Now the paperwork is part of their plan, not your problem.

Build a security packet once and use it every time

The security questionnaire is the step that pulls founders back in the most. The questions are technical, the rep can't answer them, and the founder or the lead engineer ends up writing answers from scratch. Then the next big deal sends a different questionnaire with most of the same questions.

Stop writing them from scratch. Build a packet once, keep it current, and have the rep send it before anyone asks. A good packet usually has:

  • A short security overview: where data lives, who can access it, and how it's protected.
  • Your SOC 2 report, if you have one, shared under an NDA.
  • Your main policies, like access control, backups, and incident response.
  • A summary of any outside security testing you've done.
  • A library of answers to the questions you get every time.

If you don't have a SOC 2 report yet, don't fake it and don't dodge. Say what you have, what you're working on, and when you expect to finish. Security teams deal with small vendors all the time. What they don't forgive is a surprise.

Name one person who owns the packet. It's usually a technical lead, not the founder. Their job is to keep it current and to answer the handful of questions the library doesn't cover. The rep's job is to send it, track it, and chase the reviewer for a sign-off.

Write the security answers once. Every big deal after that gets faster, and you stop being the only person who can answer them.

Start the threads in parallel

Don't wait for the formal yes. Start the paperwork when the champion confirms intent. That's the moment they say something like, "If this checks out, we want to move forward." Then, the same week:

  • Send the security packet to their security reviewer.
  • Send your standard contract to their legal team, so they can start their review now.
  • Ask procurement for their vendor forms and send back what you can right away.

Then hold a short weekly check-in with the champion. Fifteen minutes. Where is each thread? What's stuck? Who do we need to nudge? Update the deal record after every call. My rule of thumb: if any thread goes two weeks without movement, the rep asks the champion what changed. Silence on paperwork usually means a priority shifted, and you want to know now, not at quarter end.

Is there a risk you do work on a deal that dies? Sure. But a security packet you already built costs you an email. Waiting costs you weeks.

Give every step an owner, on both sides

This is where most founders get pulled back in. Every step after the yes needs a name on your side and a name on theirs. Write both into the deal record before the verbal yes. Here's the map I use.

The Late-Stage Owner Map: every step after the yes gets a name on both sides, before the yes. Security questionnaire: your side, the rep owns the deadline and a technical lead writes the answers; their side, the IT security or risk reviewer; send proactively your security packet and a library of answers to common questions. SOC 2 or security documentation: your side, a technical lead keeps it current and the rep sends it; their side, IT security, sometimes a vendor risk team; send proactively your SOC 2 report under NDA if you have one, and if not, a security overview and your honest plan. Contract redlines: your side, the rep runs the process and your attorney decides the terms; their side, their legal counsel; send proactively your standard contract early, plus the terms you can flex on, set with your attorney. Vendor setup and payment terms: your side, the rep with whoever runs your finance; their side, procurement and accounts payable; send proactively a tax form, insurance certificate, billing contact, and your standard payment terms. Final pricing pushback: your side, the rep inside written discount rules; their side, procurement; send proactively price approved before the yes and a give-get list of what you ask for in return for any discount. The rep owns the deal start to finish; the founder answers specific questions, then steps back. Owner assignments are Louie's rule of thumb, not legal advice.

The rep stays the deal owner

Other people answer questions. The rep owns the deal. That means the rep sends every document, tracks every thread, runs the weekly check-in, and updates the CRM. When the security reviewer has a technical question, the rep brings in the technical lead for that question, then takes the deal back.

This matters more than it sounds. If the buyer learns that the fastest way to get an answer is to email the founder, every question will go to the founder. And your rep becomes a messenger on their own deal.

The founder answers questions, not the whole deal

There are times the founder should show up. Their CEO wants to meet yours. A term needs a decision only you can make. Fine. Show up for that, answer it, and hand it back. Decide ahead of time which moments those are, and write them down. I lay out how in the escalation rule.

Related ReadingThe Escalation Rule: When the Founder Should Still Get on the Call →

When procurement asks for a lower price

It's coming. In a lot of bigger companies, getting a better price is part of procurement's job. They didn't sit in your demo. They don't care how much the champion loves you. They're going to ask for a discount, and they'll often ask after the champion has already said yes.

Here's how to handle it without breaking your own rules:

  • Set the price before the yes. Get the champion to agree to the number before procurement gets involved. Then procurement is pushing on a price their own people already approved.
  • Write your discount rules down. How much can the rep give without asking? What needs your approval? If the rule lives in your head, the rep has to call you, and you're back in the deal.
  • Give, then get. Never cut price for nothing. If you give a discount, ask for something back: a longer term, payment up front, a case study, a signed date this month.
  • Be ready to say no. Sometimes the answer is "That's our price." A deal that only closes at a price that hurts you isn't a deal you want to set as the anchor for every big deal after it.

I go deeper on this in the discount trap.

Let your attorney handle the legal part

I'm a sales guy, not a lawyer, and this isn't legal advice. Your attorney should review contract terms. But there's a sales side to legal that you can fix.

First, send your contract early so their legal team starts on your paper. Second, sit down with your attorney once, before the next big deal, and decide which terms you can flex on and which you can't. Write that list down. Now the rep knows what to say yes to, what to send to your attorney, and what's a hard no. Third, don't let redlines go back and forth by email for weeks. When the gap is small, a 30-minute call between the right people often closes it.

Where a Fractional Sales Leader fits

This is the kind of work I do with founders. I add the late-stage steps to your pipeline with real finish lines. I help you build the security packet and the answer library. I write the discount rules and the give-get list. And I coach your rep through the first big deal so they own it, start to finish, while you stay out of the closer seat.

I've spent 50 years in sales, including 22 years building MindIQ into an INC 500 company. The deals that got stuck after the yes almost never had a bad champion. They had no plan for what came next. Salespeople don't quit companies, they quit chaos, and a big deal with no plan is chaos with a big logo on it.

If you're still deciding whether to chase bigger deals at all, start with the upmarket readiness test. The next article in this series covers the bigger risk: how your first enterprise deal pulls you back into sales, and how to plan so it doesn't.

Frequently Asked Questions

Q: Why do enterprise deals stall after the verbal yes?

Because the yes starts three more steps: a security review, legal redlines, and procurement. Most small teams don't plan for them, run them one at a time, and have no owner for each. The deal sits in "Negotiation" while the founder chases it.

Q: Should security, legal, and procurement be stages in my CRM?

Yes. Add them as their own stages, or as a required checklist inside one late stage. Each one needs an owner, a date, and a finish line the buyer completes, like their security reviewer confirming in writing that you passed.

Q: Do I need SOC 2 to sell to bigger companies?

Not always, but it helps. In Secureframe's 2026 benchmark report, 38% of organizations said they had lost revenue or bids because they lacked a compliance certification. If you don't have SOC 2 yet, send a clear security overview and an honest timeline instead of dodging the question.

Q: Who should answer the security questionnaire?

A technical lead writes the answers, and the rep owns the deadline. Build a reusable library of answers so each new questionnaire takes hours, not weeks. The founder should only step in for the few questions nobody else can answer.

Q: How do I handle procurement asking for a discount after the champion said yes?

Expect it. Agree on price with the champion before procurement gets involved, write down your discount rules so the rep doesn't need you, and never give a discount without getting something back, like a longer term or payment up front.

Q: When should the founder get involved in late-stage paperwork?

Only for specific moments you decide ahead of time, like a CEO-to-CEO call or a contract term only you can approve. Show up, answer the question, and hand the deal back to the rep. The rep stays the deal owner from first call to signature.

Related ReadingShould You Chase Bigger Deals Yet? The Upmarket Readiness Test →

Is a big deal stuck after the yes?

In 30 minutes we'll map your late-stage steps, name an owner for each one, and find where your deal is stuck.

Schedule a 30-Minute Call

About the Author

Louie Bernstein

Fractional Sales Leader with 50 years of sales experience helping $1M–$10M ARR companies build scalable, repeatable sales systems. Founder of MindIQ (INC 500). LinkedIn Top Voice in Sales Management, Sales Operations, and Sales Coaching.

LinkedIn  |  Subscribe to The Sunday Starter  |  YouTube